Wadira: Find your way through Saudi data & privacy law.

HomeFrameworksCybersecurity › Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation

Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation

TypeGuideline
Issuing authorityNational Cybersecurity Authority (NCA)
FrameworkCybersecurity
TierGuidelines & circulars
Legal statusGuidance

The Guide to Organizations' Social Media Accounts Cybersecurity Controls Implementation (GOSMACC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Organizations' Social Media Accounts Cybersecurity Controls (OSMACC-1:2021), which set the minimum requirements for organisations' safe official use of social networks.

The guide presents the OSMACC domains and subdomains: cybersecurity governance (policies and procedures, risk management, human resources, and awareness and training), cybersecurity defence (asset management, identity and access management, protection of information systems and processing facilities, mobile-device security, data and information protection, event-log monitoring, and incident and threat management) and third-party cybersecurity, then provides a general implementation guideline followed by guidance under each domain. It supports the OSMACC's ECC-aligned compliance model, in which continuous compliance with the Essential Cybersecurity Controls is a prerequisite.

Documents

In this framework


Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13